2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-55488MEDIUM6.5A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scrip...
CVE-2024-42013MEDIUM6.4In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attac...
CVE-2024-42012MEDIUM5.7GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is c...
CVE-2024-10929MEDIUM5.1In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may ...
CVE-2024-24432MEDIUM5.3A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service...
CVE-2024-13447MEDIUM4.3The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2024-13360MEDIUM5.4The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ...
CVE-2024-13319MEDIUM6.1The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg...
CVE-2024-13406MEDIUM6.1The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id...
CVE-2024-12117MEDIUM5.4The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-12879MEDIUM4.3The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2024-13590MEDIUM5.4The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' short...
CVE-2024-13584MEDIUM5.4The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-13426MEDIUM5.3The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2...
CVE-2024-49736MEDIUM5.5In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a lo...
CVE-2024-49733MEDIUM5.5In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to ...
CVE-2024-43763MEDIUM6.5In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This coul...
CVE-2024-24443MEDIUM6.5An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface ...
CVE-2024-45478MEDIUM4.8Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended ...
CVE-2024-24445MEDIUM6.5OpenAirInterface CN5G AMF (oai-cn5g-amf) <= 2.0.0 contains a null dereference in its handling of unsupported NGAP protoc...
CVE-2024-57545MEDIUM5.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_nu...
CVE-2024-57544MEDIUM5.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is...
CVE-2024-57543MEDIUM5.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) ...
CVE-2024-57541MEDIUM5.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_s...
CVE-2024-57540MEDIUM6.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is cop...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now